Back

HIGH

In Kitty before 0.26.2, insufficient validation in the desktop notification escape sequence can lead to arbitrary code execution

Published Sep 23, 2022

Description

In Kitty before 0.26.2, insufficient validation in the desktop notification escape sequence can lead to arbitrary code execution. The user must display attacker-controlled content in the terminal, then click on a notification popup.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (8)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 23, 2022
Updated Jun 1, 2025
Reserved Sep 23, 2022
CISA Vulnrichment
Updated May 27, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a